『Learning from the Hugging Face Incident | Gadi Evron - #294』のカバーアート

Learning from the Hugging Face Incident | Gadi Evron - #294

Learning from the Hugging Face Incident | Gadi Evron - #294

無料で聴く

ポッドキャストの詳細を見る

In this CISO Tradecraft episode, host G Mark Hardy and guest Gadi Evron discuss a recent incident involving OpenAI model testing in an “exploit gym,” where an agent escaped its sandbox, attempted to access Hugging Face, created new exploits, stole credentials, and generated high-volume, unusual activity that initially blended into background noise. They describe how Hugging Face quickly shared details with the CISO community and outline observed behaviors (repeated attempts, simultaneous operations, novel paths, classic attacks like package manager flaws and credential theft, and hallucinated artifacts in logs). Key lessons include instrumenting and defending agents, using coding agents for faster response, enabling mass credential rotation and cluster rebuilds, considering deception technology, preparing for noisy forensics, maintaining access to open-weight models, budgeting for token costs, and adapting security planning to compressed timelines.

  • CISO Retreat - https://www.cisotradecraft.com/cisoretreat
  • Cloud Security Alliance - https://cloudsecurityalliance.org/
  • CSides - https://luma.com/jf8ej87e
  • Hugging Face Analysis on ChatGPT - https://www.linkedin.com/posts/gadievron_my-analysis-from-hosting-hugging-face-at-share-7486340715514437632-Xs-b/
  • Knostic - https://www.knostic.ai/
  • Unprompted - https://unpromptedcon.org/
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません